Repository navigation
Security: CircleCI-Public/mcp-server-circleci
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Remote transport serves to unauthenticated non-browser clients when request auth is disabled (Host/Origin bypass)GHSA-xv5j-cwgj-22r4 published
Aug 10, 2026 by sbeaulieCritical -
Path Traversal / Arbitrary File Write in mcp-server-circleciGHSA-4pxc-9x5p-39fc published
Aug 7, 2026 by djdavisciHigh -
Unauthenticated command injection in run_evaluation_tests leads to RCE in the CircleCI runnerGHSA-m9x7-h9px-p447 published
Jul 22, 2026 by sbeaulieCritical -
DNS rebinding allows invocation of MCP tools using the server-held PATGHSA-jwj7-74jh-p5c4 published
Jul 22, 2026 by sbeaulieHigh -
Missing destructiveHint annotations on destructive MCP toolsGHSA-8xjg-jpfh-5257 published
Jul 20, 2026 by sbeaulieModerate
Learn more about advisories related to CircleCI-Public/mcp-server-circleci in the GitHub Advisory Database